Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2021-10-20 CVE-2021-1968 Improper Input Validation vulnerability in Qualcomm products
Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-20
5.5
2021-10-20 CVE-2021-1969 Improper Input Validation vulnerability in Qualcomm products
Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-20
5.5
2021-10-20 CVE-2021-30305 Improper Input Validation vulnerability in Qualcomm products
Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-20
7.8
2021-10-13 CVE-2021-41138 Improper Input Validation vulnerability in Parity Frontier
Frontier is Substrate's Ethereum compatibility layer.
network
low complexity
parity CWE-20
5.3
2021-10-13 CVE-2021-33609 Improper Input Validation vulnerability in Vaadin
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.
network
low complexity
vaadin CWE-20
4.3
2021-10-12 CVE-2021-42009 Improper Input Validation vulnerability in Apache Traffic Control
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitrary body to an arbitrary email address.
network
low complexity
apache CWE-20
4.3
2021-10-11 CVE-2021-42257 Improper Input Validation vulnerability in Check Smart Project Check Smart
check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.
local
low complexity
check-smart-project CWE-20
7.1
2021-10-04 CVE-2021-21705 Improper Input Validation vulnerability in multiple products
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid.
network
low complexity
php netapp oracle CWE-20
5.3
2021-09-30 CVE-2020-18683 Improper Input Validation vulnerability in Atlassian Floodlight
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.
network
low complexity
atlassian CWE-20
critical
9.8
2021-09-30 CVE-2020-18685 Improper Input Validation vulnerability in Atlassian Floodlight
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.
network
low complexity
atlassian CWE-20
critical
9.8